Re: [mod-security-users] IS this firewall code bullet proof
Brought to you by:
victorhora,
zimmerletw
|
From: Ivan R. <iva...@gm...> - 2006-04-17 16:59:49
|
Thank you all for your support. Let us forget about this little incident and continue as usual. I've been busy rewriting major parts of ModSecurity code. In a week's time I should have another development version for you to test. The bad news is that v2.0 wil not be backward compatible. I have taken this opportunity to remove some of the old baggage and a lot of small things that did not make sense (but were a byproduct of the evolution process). The good news is there are many exciting improvements. For example: 1. No more built-in normalisation features. One is now able to configure normalisation options exactly as it is needed. Plus, there are several new normalisation options. 2. Processing is split into five phases. One of the phases now runs immediatelly after Apache receives a request. 3. Support for XML processing, DTD and Schema validation, XPath expressions= . -- Ivan Ristic, Technical Director Thinking Stone, http://www.thinkingstone.com ModSecurity: Open source Web Application Firewall |